OpenCode Go usage works again for accounts moved to OpenCode's Console workspace. The taskbar flyout also stays readable when Windows reports a light taskbar color.
Fixed
OpenCode Go usage after the Console migration. Ceiling reads the current Console usage API and uses the legacy workspace page when appropriate. Thanks to @Redbirdma.
Taskbar flyout contrast on light themes. The flyout keeps an opaque dark background with a subtle taskbar tint, so labels and meters remain readable. Fixes #468. Thanks to @jayn2u.
Full Changelog: https://github.com/btsouth/ceiling/compare/v1.5.39...v1.5.41
The main window now recovers from a WebView2 crash the same way the flyout, Settings, and FloatBar already do, and every window reacts the moment its browser process fails instead of on the next open. Secrets stored through the keychain now reach Windows Credential Manager, Antigravity failures finally say what went wrong, and WSL distros with a custom mount root find their Windows-side usage again.
Fixed
The main window rebuilds itself after a WebView2 crash. It was the one window 1.5.38 could not recover, because its open paths run where building a window inline would deadlock. The rebuild now runs off-thread and replays whatever the user clicked once the new window is up. Ceiling also listens for WebView2's ProcessFailed event, so a visible window is rebuilt right away and a hidden one is torn down before it is next opened. Thanks to @diogochaves. Part of #410.
Keychain secrets are stored in Windows Credential Manager. The keyring library was built without its Windows backend, so every entry landed in an in-memory store: keychain API key lookups and the Claude credential entry never found anything, and the StepFun token cache was lost on exit. Entries now go to Credential Manager.
Antigravity failures say what actually failed. Both language server calls dropped their errors, so a signed-out server, a changed response, and a timeout all read "returned no user status and no quota summary". The panel now shows the HTTP status or the shape of the failure, and diagnose -p antigravity carries it too. The reset time a
Codex usage keeps reading correctly through OpenAI's latest response changes, and the Antigravity CLI is recognized when Windows cannot read its process command line. A Windows rendering failure also gets a recovery path: the flyout, Settings, and FloatBar windows rebuild themselves after their WebView2 process exits instead of staying blank, and the taskbar flyout no longer leaves a strip of desktop showing under its last row.
Fixed
The flyout, Settings, and FloatBar rebuild themselves after a WebView2 crash. Windows keeps a Tauri window's frame after the WebView2 browser and render processes exit, but the client area then paints nothing, and because these windows are hidden rather than closed the dead frame was reused on every open. Each window now checks for a live render host before opening and destroys the dead frame so a fresh one is built. Fixes the blank frame for those windows in #410; the main window needs an async rebuild path and remains open.
Codex usage keeps reading through OpenAI's latest response changes. The usage endpoint renamed and moved several fields, and the old parser silently dropped them: a quoted credit balance never rendered, the spend limit under spend_control.individual_limit and the top-level code-review meter were ignored, and Spark's weekly window was discarded. Those are read again, Spark is matched by its new codex_bengalfox meter, and numeric fields that arrive as strings still parse. Fixes #441.
The Antigravity CLI is detected even when Windows cannot read its command line. Th
Charts stops showing numbers it cannot stand behind. A month whose models have no published prices painted as an empty one, the busiest day on the activity heatmap could share a shade with the quietest, and a Codex session carried whatever calendar day it was first parsed on, so a DST change or a trip moved usage onto the wrong day. Two cards scanning at once could overwrite each other's index, and a price refresh landing mid-scan stamped old dollars as current for every card already in the file.
The rest is state a surface reported but could not actually reach. A settings or credentials write could run unserialized on a filesystem that cannot flock, Install and Restart could check a staged installer against a different release's digest, and dismissing an update mid-download un-dismissed itself on the next progress chunk. A machine reporting no home directory no longer reads Gemini credentials from — or writes refreshed Google tokens into — whatever directory it happened to start in.
Ceiling also asks for a GitHub star now. At most twice, ever, and only after a provider has actually reported a reading.
Added
Ceiling asks for a GitHub star, at most twice ever. A card in the bottom-right of the dashboard, and the only thing Ceiling has ever asked of anyone using it. The first ask waits until a provider has actually reported a reading and that reading has been on screen for twenty seconds, so it lands after the app has done something useful rather than during setup, when it would be asking to be paid before the work. The second,
Charts opens in about two seconds instead of about thirty. Each local transcript is now parsed once into a small index beside your settings rather than re-read from the top by every card, every time, and the cards keep their last result so a restart is not a cold start. The numbers are unchanged: an indexed scan is checked against a full re-parse, and the index is discarded outright whenever model prices move.
The rest of this release is about surfaces reporting a state they could not actually reach. Signing out of StepFun could leave a live token behind if a refresh was in flight, Gemini treated a token endpoint it could not reach as a signed-out account, a countdown could read "0m" while a window still had a minute in it, and About labelled a failed download as a failed update check and said it in half-translated English.
Fixed
Charts opens in a couple of seconds instead of half a minute. On a machine holding gigabytes of Codex and Claude transcripts, opening Charts started three separate walks of the same logs at once, and each one read every file from the top: Estimated API value scanned ninety days when the furthest period it shows reaches back sixty, the activity heatmap scanned thirty, and the provider charts scanned again on top. Nothing was kept, so switching tabs paid for all of it again, and clicking Yesterday or 30 days re-ran a full scan for numbers the card already had in hand. Each transcript is now parsed once and its records are kept in a small index beside your settings; a file that grew since is resumed from w
Adds an activity heatmap to Charts and an opt-in spend warning that needs no budget set, and lets the floating bar follow whichever app you are working in. Mostly, though, this release stops surfaces reporting a state they could not actually read: a provider outage is now told apart from an empty quota, a missing Cursor plan reads as unavailable rather than 0% used, SuperGrok's weekly figure is decoded rather than guessed at, the taskbar strip stops cutting the last character off a reset, and prices, chart caches, and CLI logs stop losing or hoarding data on disk. Release builds also drop the loopback exception their content policy was carrying from the dev server.
Supersedes 1.5.32. That version was tagged, signed, and drafted on 2026-08-16, and its installers were uploaded to the versioned download path, but the GitHub release was never published and no one received it. The v1.5.32 tag stays as a marker. Everything from it is included here, plus the taskbar reset fix that was found in its build.
Added
Providers having a public outage get a badge on their card. A "0 tokens left" reading and a provider outage looked identical, so the second was read as the first. The provider card now carries the status page's own wording, plus a control that opens that page. Off by default and opt-in under Notifications, because it is the only outbound request Ceiling makes that is not to a provider you already signed in to. Nothing about you is sent. Only enabled providers whose status page can actually be read are polled, at most once every
Hardens updates, credentials, and the local serve API, and ships the unpublished 1.5.30 work: a second tray click hides the dashboard, Grok banked resets show, and the taskbar strip finds a second lane when the usual gap is gone.
Supersedes 1.5.30. The GitHub release was tagged and drafted on 2026-08-13 but never published; the v1.5.30 tag stays as a marker. A Microsoft Store submission was created from that tag. Everything from it is included here.
Security
Ceiling checks who signed an update before it runs it. An automatic update was trusted on the strength of the SHA256 that GitHub's release metadata reported, so that metadata was the only thing standing between Ceiling and launching an attacker's installer with the user's privileges. Every downloaded installer is now independently checked against Windows Authenticode and pinned to Ceiling's publisher identity, once when the download completes and again immediately before launch. An installer that fails either check is deleted instead of being left on disk to be retried. The publisher identity is pinned rather than the signing key, because Azure Trusted Signing issues a fresh short-lived leaf certificate for every release and a key pin would reject the next legitimate one.
codexbar serve now requires a per-user bearer token. The local HTTP API bound to loopback with only a Host check, so any process on the machine could read usage, email, organization, and raw provider errors. /usage and /cost now need Authorization: Bearer unless you pass `--allow-unauthentic
Finishes what 1.5.27 started: Cursor's on-demand spend now reads as money on every surface that shows it, not only the Overview card. Also lets a monthly quota raise a pace warning, and gives every settings control a name a screen reader can reach.
Supersedes 1.5.28, which was tagged but whose build was cancelled before it signed or published anything; everything from it is included here. The v1.5.28 tag stays as a marker.
Fixed
Cursor's on-demand spend reads as money on the taskbar, not just on the Overview. 1.5.27 taught the Overview card to show dollars, but the surfaces you actually glance at were left behind. The taskbar tile picked the on-demand lane correctly and then drew "62%" � the fraction of a spend cap, which says nothing about the $1,112.92 behind it, and which inverts to a cheerful "38%" if you display remaining rather than used. The flyout was worse: it discarded any lane whose name contained "on-demand" before building its rows, so the tile named a lane that the panel beneath it refused to show, and because the same filter ran before the "+N more limits" count, nothing hinted that a row had been dropped. The free-floating bar carried the identical percentage-only defect. Activity had the same habit from the other direction: it listed the On-demand row faithfully and then headlined it "56% used", describing the shape of the bar instead of the bill. A lane billed in currency now leads with the amount on every surface that shows it � taskbar tile, hover flyout, floating bar, and the Activity schedule � the flyout
Makes Cursor's on-demand spend readable at a glance, corrects two numbers Ceiling was reporting wrong, and replaces browser cookie import with a manual setup you can see.
Supersedes 1.5.26, which was built but never published; everything from it is included here.
Changed
Browser cookie import is gone, replaced by a manual copy-and-paste setup. Ceiling could read cookies out of the browser's own database to authenticate a provider, and provider fallbacks could reach for that database without being asked. Handing an app your browser's cookie store is a large amount of trust for a usage meter, and it happened where you could not watch it. Providers that need a cookie now ask for one, with a guide for copying it out of the browser's developer tools, and the value goes to the same secure store as every other credential. If a provider was authenticated by browser import, it will ask you to set it up again. Everything else is untouched: CLI credentials, IDE credentials, OAuth sign-in, and Claude Desktop sessions are all still detected automatically, and providers on those paths need no attention.
Added
Tab strips can be driven from the keyboard. Settings, the Charts provider selector, the account switcher, and the chart-type tabs all announced themselves as tab strips to assistive technology while ignoring arrow keys entirely, and each one spent a Tab stop per tab. Left and Right move between tabs, Home and End jump to the ends, focus wraps, and a strip is now a single Tab stop. Each panel names the tab that opened it, a
Claude's taskbar tile now shows the capacity that governs your account
Claude's model-specific limits, such as "Fable only," could take over the single taskbar lane when they reached 100%. That hid Session and Weekly capacity even though switching models still let you work. The native taskbar tile and floating bar now reserve that lane for the real account pools; model limits remain visible everywhere that lists all windows.
Credential and settings updates no longer risk unrelated data
An unreadable API-key or manual-cookie store is left untouched instead of being treated as empty and overwritten.
Unknown provider settings and token accounts survive saves and downgrades instead of resetting preferences or disappearing.
Removing one token account preserves the account you actually selected.
Custom Codex endpoints are checked by their real host
Plaintext custom Codex URLs are restricted to genuine loopback hosts. URL shapes that merely contain localhost while pointing at a remote host are rejected, preventing the Codex access token from being sent there. Legitimate local proxies continue to work.
Also fixed
Countdown formatting no longer loses nearly an hour around hour boundaries.
Relative reset timers hold at one minute instead of displaying "Resets in 0m."
Installers
Ceiling-1.5.25-Setup.exe - standard installer
Ceiling-1.5.25-portable.exe - portable
Ceiling-1.5.25-Store-Setup.exe - Microsoft Store package (WebView2 bundled)
Portable builds show alerts as banners but do not keep them in the notificat
This release supersedes 1.5.23, which was never published — everything from it is included here.
Your usage bars now show where you *should* be
Ceiling could already work out whether you were on course to run out before a window reset. It just wasn't on the thing you actually look at.
Every weekly and monthly bar — in the Overview and in a provider's detail view — now carries a marker for where usage should be at this point in the window. One rule, everywhere: the marker is where the bar's edge should be right now.
Edge sitting at the marker → you're on pace.
Edge past it → you're ahead of budget, and the overspend fills in as a striped band, so you can see *how far*, not just *which side*.
Bars set to show remaining capacity mirror the marker, so it means the same thing either way.
It's worked out from elapsed time against the window's own length, which means it needs nothing from the provider and shows up on every long window at once, instead of only the single window a pace prediction was calculated for.
Five-hour session bars are deliberately left plain. Nobody spends a session evenly, so a marker there would drift across the bar all afternoon and tell you nothing.
Predictive pace warnings are back, if you want them
Under Settings → Notifications, "Predictive Pace Warnings" alerts you when a window is on course to be exhausted before it resets. It's off by default.
This existed but was unreachable: switched off on every launch with no way to enable it, and limited to Claude and Codex even then. Any provider that reports a re
A lightly used OpenCode Go account could report its rolling window as 100% used while the dashboard showed 1%. The usage page reports each window as either whole percentages or fractions of the limit, and a lone 1 means 1% in one and 100% in the other. The per-window scaling rule turned the first 1% of use into a maxed-out rolling window.
The scale is now resolved once per response from real evidence in the payload, and only read as fractions when a window actually holds a fractional value. The same bug was present in the OpenCode, Qoder, Chutes, and Sakana providers, and it is fixed for all of them.
OpenCode Go's monthly window has a name
The OpenCode Go card now labels its monthly bar "Monthly" instead of the generic "Extra", so the third usage window on that card is no longer anonymous.
The Store build submits again
The 1.5.21 Microsoft Store submission was rejected because Partner Center caps installer parameters at 40 characters and the inherited value was longer. The parameters are now normalized to that limit, with startup-prompt suppression and the restart-required exit code preserved, and a deterministic Store-package preparation test guards it in CI.
Installers
Ceiling-1.5.22-Setup.exe - standard installer
Ceiling-1.5.22-portable.exe - portable
Ceiling-1.5.22-Store-Setup.exe - Microsoft Store package (WebView2 bundled)
Portable builds show alerts as banners but do not keep them in the notification center. That requires the Start Menu shortcut installed by the s
Ceiling could send the same reset notification two or three times. One quota window confirmed its reset while another was still awaiting confirmation, so the confirmed window's old baseline survived long enough to replay the same reset.
Each confirmed window now advances independently, and a second guard suppresses replay of the same scheduled reset cycle.
Safer local state
Ceiling now replaces settings, credentials, history, geometry, and cache files atomically. If the app or Windows interrupts a save, the previous complete file remains available instead of being replaced by a partial one.
Account history stays with the right account
Chart history, quota-run efficiency, and caches now consistently use the stable account ID, falling back to email or organization when needed. This prevents seats that share an email from blending data and restores history for organization-only providers.
Claude refresh failures stay contained
Claude now reports HTTP client setup failures instead of panicking a background refresh task, and OAuth credential refreshes use reliable atomic replacement on Windows.
Installers
Ceiling-1.5.21-Setup.exe - standard installer
Ceiling-1.5.21-portable.exe - portable
Ceiling-1.5.21-Store-Setup.exe - Microsoft Store package (WebView2 bundled)
Portable builds show alerts as banners but do not keep them in the notification center. That requires the Start Menu shortcut installed by the standard or Store build.
Claude accounts no longer report themselves as maxed out
An account sitting at 1% could show its 5-hour session as 100% used, and raise an exhausted alert for it.
Anthropic reports usage as either whole percentages or fractions of the limit, so a lone 1 means 1% in one and 100% in the other. Ceiling guessed wrong whenever every window was still at 0 or 1, which is exactly what a lightly used account looks like.
Notifications stay in the notification center
1.5.17 was meant to fix Windows throwing Ceiling's alerts away. On a clean install it did nothing.
Windows only keeps a notification for an app it can identify, and it reads that identity from a Start Menu shortcut. The installer was not setting it, so a fresh install still lost every alert seconds after it appeared. It only looked fixed on machines that had an older shortcut left behind.
If you are on 1.5.17, install this one to pick up the corrected shortcut.
Updates no longer loop
Running Ceiling from somewhere other than the installed folder, such as a local build or an install from older packaging, put updates in a circle. The installer succeeded elsewhere, the copy you were running stayed on the old version, and the same update came back on the next check with nothing on screen explaining why.
Ceiling now spots that and names both copies instead of quietly repeating itself. Cached installers are cleaned up once superseded, too. They were kept forever, and one machine had 305 MB of them.
If a reset alert flashed past while you were looking elsewhere, it was gone for good. Ceiling's toasts appeared as a banner for a few seconds and never reached the Windows 11 notification center.
They were published under an app identity Windows did not recognise, so it showed the banner and then discarded it. 1.5.17 publishes under the installed app's real identity, so alerts collect in the notification center like every other app, and repairs the setting on launch if Windows already marked Ceiling as banner-only.
Toasts also carry the Ceiling name and logo now, instead of arriving as unattributed text.
Resets you were actually waiting for
Two changes so the alerts that matter get through:
A confirmed reset is no longer dropped. Providers refresh at the same time, and only one alert was allowed per refresh, so an unrelated warning could silently swallow the only weekly reset notification you would get all week.
Scheduled 5-hour session resets no longer notify. They come round several times a day and are exactly what you already expect. Weekly and monthly resets always notify, and unexpected ones (early, partial, banked) still notify at any cadence.
Portable builds are a deliberate exception. Windows only keeps notifications for an app claimed by a Start Menu shortcut, and Ceiling will not add one to a machine where you chose portable. Portable alerts appear as banners without notification-center history.
Simplified Chinese
中文 is now a switchable interface language under Settings > General.
Taskbar that shows the limit that actually binds you
Native strip tiles now pick the tighter window (5h session vs weekly) instead of always showing the primary bar. A maxed weekly pool no longer looks like free 5h capacity.
You can also pin which Codex or Claude account drives each strip tile (Settings → Taskbar). The flyout marks that seat On strip and lists it first. Strip labels stay short (window + optional reset) so long account names stop colliding with the next provider.
Grok charts with real dollar estimates
Charts → Grok still shows tokens, cache mix, reasoning, effort, and projects from local Grok Build sessions. It now also shows API-equivalent cost, the same Cost figure Grok Build prints in /usage.
That dollar total is a rate-card estimate, not SuperGrok subscription spend. The weekly pool meter on the strip is still the source of truth for how much pool you have left. Sessions that never logged full usage stay unpriced, with a clear coverage note when that happens.
The Estimated API value card on Charts now includes Grok next to Codex and Claude.
Charts trust and efficiency
Period cards show N% of tokens priced when some models lack a public rate, so a partial dollar total does not look exact.
New Quota run efficiency card: tokens per 1% used during a completed limit run, cache-read share, projected tokens at 100% once the run has enough data, and change vs the previous run on the same window. Local observation only.
Grok is now a full peer of Claude, Codex, and Cursor: tray, popout, taskbar strip, charts, and plan detection from your SuperGrok account.
Sign in with a normal grok login (or provide grok.com cookies). Ceiling refreshes the OIDC token from ~/.grok/auth.json the same way it handles Claude. SuperGrok Heavy weekly pool usage shows a Weekly meter with the correct reset. The plan name (for example SuperGrok Heavy) is read from your account when available.
The official Grok monogram is used across the tray, overview, providers, charts, and taskbar strip. The strip can hold five providers so Grok can sit after Cursor, with Settings → Display controls to pick and reorder which ones appear.
Local Grok usage on Charts
Charts → Grok now scans local Grok Build sessions under ~/.grok/sessions for:
tokens over the last 7 and 30 days (and the current weekly window)
cache vs fresh input mix
reasoning tokens and reasoning-effort tiers (high / medium / low)
project rollups from each session's working directory
This is SuperGrok pool usage measured in tokens, not a dollar bill. There is no public API rate card for pool usage, so model rows stay unpriced. Weekly pool percent samples still feed the Limits series as before.
Fixes
Grok no longer shows Extra credits for the weekly pool. The bar and popout label read Weekly.
Empty cookie settings no longer force a "CLI not supported" path when you already have a grok login session.
Weekly pool responses that omit a zero percent reading show 0% with the correct weekly reset instead of
Ceiling can now watch more than one Codex or Claude account at the same time, from a new Accounts tab. Both accounts show side by side, so you can keep an eye on a personal and a work seat together.
An account is a config directory (CODEX_HOME for Codex, CLAUDE_CONFIG_DIR for Claude) rather than a token you paste, because each CLI refreshes its own sign-in in place and a copy would go stale within hours. To add one, run this in PowerShell:
then point Ceiling at that folder. It reads the name and plan off the folder itself, so there is nothing to type, and it checks the folder first to tell you whose account is in it. Your currently signed-in account is listed automatically, so adding a second one leaves you with two rather than replacing the first. Each provider card names its account by email, with an optional accent color.
Also in this release
Reset-while-closed notifications. A reset that happened while Ceiling was closed is now reported, saying when it actually happened ("This happened at 2:00 AM, while Ceiling was closed") instead of staying silent.
Per-account usage alerts. With two accounts on one provider, a quiet account was clearing a busy account's pending threshold alert, so the warning never fired.
Correct Claude sign-in when CLAUDE_CONFIG_DIR is set.
No cross-account bleed. Two accounts no longer share a usage baseline, a transient auth error can't substitute the other account's data, and the usage chart no longer falls ba
Two Codex accounting corrections and a new disclosure when a machine's local totals cover more than one plan.
Added
Ceiling now tells you when local totals cover more than one subscription plan. Codex records the plan behind each request, so if a machine has been used by more than one, the Charts page says so rather than letting the figures read as the signed-in account's. Local logs never record which *account* produced them, so this reports what was seen and does not guess.
Fixed
Count Codex cached input once when working out a model's cache rate. Codex reports cached tokens inside its input count, and adding the cache bucket on top counted them twice, so a model that was really about 97% cached displayed as 49%.
Include archived Codex sessions in the Charts page, the reset windows, and the estimated API value. Only the active sessions folder was being read there, so archiving a task quietly shrank every total while the older summary still counted it.
Say which window each cache percentage measures. The per-model figure covers 30 days while the token mix above it covers 7, and they can legitimately differ.
Note on your numbers going up
The archived-sessions fix will increase your totals if you archive Codex tasks. On one test machine 81 of 97 rollouts were archived and therefore invisible to the Charts page. This is a correction to figures that were previously too low, not new usage.
Signed builds for Windows 10 and 11. Verify downloads with the .sha256 sidecars.
Full changelog: https://github.com/tsouth89/ceiling/compare/v1.3.2...v1.4.
The Today / Yesterday / 30 days buttons on the Charts page no longer jump between rows. Picking a period with no change to report made the card shorter, which removed the page scrollbar, widened the content, and reflowed the header above it. The card now keeps one height across every period and metric, and the heading wraps its own text long before the buttons move.
Signed builds for Windows 10 and 11. Verify downloads with the .sha256 sidecars.
Full changelog: https://github.com/tsouth89/ceiling/compare/v1.3.1...v1.3.2
Supersedes 1.3.0, which was withdrawn before general release. If you are on 1.2.1, this is the upgrade.
Added
See estimated API-value dollars beside the token count on every usage period, including each provider's current 5-hour and weekly reset window, so you know what you have spent since your last reset. Models without a public price stay excluded rather than reading as $0.00.
The Estimated API value card now carries a seven-day trend and keeps idle providers in its legend, so a single active provider no longer leaves the card looking blank.
Changed
Compare cards are labeled as rolling windows and now say plainly that they put both providers on one shared clock, rather than each provider's own reset boundary. Reset-aligned figures live in each provider's chart drill-in.
The floating bar and overview tiles surface the window that is actually constraining you. An exhausted window wins over one that merely reads higher, and an exact tie goes to whichever resets first.
Fixed
The Compare tab loads again. It had been stuck on "Comparing local history", waiting on rolling comparison data that was no longer being produced.
Long reset timestamps no longer run across the neighbouring usage cards. The detail line wraps inside its own card, and the dollar figure sits on its own line instead of breaking mid-value.
A freshly reset Claude window no longer briefly reads as 100% full. Anthropic reports usage as either a fraction or a percentage, so a lone 1 (meaning 1% used) was being read as 100%, which also fired a false "limit reached" notification. The
A small fix on top of 1.2.0 for anyone with a lot of projects.
Fixed
Collapse the "Cost by project" list to the top 8 projects behind a "Show all" toggle, so a long project list no longer pushes the charts far below the fold.
Full changelog: https://github.com/tsouth89/ceiling/compare/v1.2.0...v1.2.1
See how long a running-low window will last, split your spend by project, and export it. This release builds on 1.1.0's spend analytics and sharpens the day-to-day signals.
Added
Show a concrete "about ~42m left" estimate in Calm mode and on the dashboard, so a running-low window tells you roughly how long you have instead of just flagging it.
Break down 30-day spend by project, alongside the existing per-model and per-effort views, using the working directory recorded in each session.
Export a provider's 30-day spend to a CSV in your Downloads folder from the charts view, covering period totals and the per-model, per-effort, and per-project rows.
Add a cache-only statusline command that prints remaining capacity for editor status bars from the last saved snapshot, without waking the app or hitting the network.
Show a Cursor activity-by-model card from local request logs, framed as activity share rather than tokens or spend.
Changed
Leave estimated cost blank for models without a public price everywhere spend is shown, including the new project view and the CSV export, so unpriced usage never reads as $0.00.
Fixed
Reset the Codex project attribution when a child or forked session has no working directory of its own, and ignore filesystem roots, so spend is bucketed to the right project.
Full changelog: https://github.com/tsouth89/ceiling/compare/v1.1.0...v1.2.0
Local spend analytics for Codex and Claude: see what your usage is worth at API rates, broken down by model, by effort, and across Today / Yesterday / 30 days. Dollars are an API-equivalent estimate from your local logs, not a bill.
Added
Show a total estimated API-value card that aggregates local usage across Codex and Claude, with Today, Yesterday, and 30-day views, an API value or Tokens metric, a provider ring, and a ranked legend.
Break down 30-day spend by model, and by Codex reasoning effort, each with a running total and clear "Not priced" rows for models without a public rate.
Surface pricing coverage (for example, "96% of tokens priced") and name the unpriced models, so estimated totals stay transparent.
Changed
Label token-derived dollars as estimated API value, not a bill or subscription spend, across the new cost views.
Fixed
Stop counting a child or sub-agent session's replayed parent history, which could inflate Codex token and cost estimates many times over.
Include archived Codex sessions and de-duplicate rollouts across locations, so 30-day usage is neither under-counted nor double-counted.
Stop reporting dollars for models without a canonical price (their tokens are still counted), so a period of only unpriced usage no longer reads as $0.00.
Attribute Codex usage to the real reasoning-effort tier recorded in the session logs instead of guessing from the model name.
Full changelog: https://github.com/tsouth89/ceiling/compare/v1.0.0...v1.1.0
Show Codex banked reset credits across Ceiling, including an explicit zero state.
Notify when new banked reset credits are confirmed.
Reliably deliver unexpected-reset and banked-reset alerts through the Windows notification pipeline.
Add a Settings test that reports when Windows has blocked Ceiling notifications.
Add Exact and Calm floating-bar information modes.
Show tracked limits as unavailable when a provider temporarily omits them instead of silently removing them.
Before you install
This is a release candidate for Ceiling 1.0. Windows notifications must be enabled for Ceiling to receive reset alerts.
Choose the signed installer for a normal installation or the signed portable executable for a standalone launch. Please report problems through GitHub Issues.
Full changelog: https://github.com/tsouth89/ceiling/compare/v1.0.0-rc.1...v1.0.0-rc.3
First release candidate for Ceiling 1.0. If you are on 0.43.x, this is a normal update.
New
First-run checklist on the empty dashboard that guides you through enabling the providers you use, connecting or confirming sign-in, and turning on the floating bar.
A "How Ceiling gets this data" panel on each provider, plus a data-sources doc, so you can see where each provider's usage comes from and what stays on your PC.
Improved
Dropdowns and checkboxes now match the app theme in both dark and light mode.
English-only build. The unused non-English locale files are gone.
Cookie docs rewritten to match how Chromium App-Bound Encryption actually works on current Windows.
Fixed
The dashboard no longer reopens at its smallest size.
Clearer empty state when no browser cookie is saved.
Install
Download Ceiling-1.0.0-rc.1-Setup.exe (installer) or Ceiling-1.0.0-rc.1-portable.exe (portable). Both are code-signed, with SHA-256 files attached.
This is a release candidate, so please report anything that looks off before the final 1.0.
First stable build of the 0.43.3 line, headlined by a full pass of Windows security hardening, plus the Charts, floating-bar, and reliability work from the 0.43.3 betas.
Security
Secret files (API keys, manual cookies, and settings) are now locked to your Windows user with a restricted NTFS ACL and encrypted with user-scoped DPAPI, with no machine-scope fallback.
The optional PowerToys status pipe is restricted to your user, so other local processes can no longer read usage and cost snapshots.
Credentials left in older settings files are migrated into the dedicated encrypted stores, leftover plaintext cookie caches are removed on startup, and temporary cookie databases are wiped on every exit path.
Each window can call only the commands it needs, and opening folders is limited to Ceiling's own locations.
Updated serde_with to 3.21.0 to resolve GHSA-7gcf-g7xr-8hxj.
Added
Persistent quota history and processed-token summaries in Charts.
Compact, standard, and detailed floating-bar density presets with automatic contrast.
Taskbar-aware floating-bar placement across primary and secondary Windows taskbars.
Changed
Replaced API-equivalent dollar estimates with processed-token and cache-traffic breakdowns.
Reworked floating-bar recovery around Windows events instead of repeated z-order writes.
Fixed
Corrected malformed chart time labels and kept provider charts responsive while history loads.
Kept Codex's regular weekly limit distinct from Codex Spark Weekly so scheduled resets notify reliably.
Ceiling keeps your AI subscription limits visible without turning them into another dashboard you have to babysit. Check capacity from the tray, keep the compact strip above the taskbar, or open the full dashboard when you want more detail.
Highlights
Always-visible capacity strip: A polished, taskbar-adjacent view of current usage and reset timing that stays out of the way.
Clear desktop dashboard: Overview, Activity, Accounts, and Charts surfaces with explicit live, cached, stale, and unavailable states.
First-class provider tracking: Focused setup and credential discovery for Codex, Claude, Cursor, Gemini, and GitHub Copilot.
Better Cursor visibility: Separate Plan, Auto, and API usage lanes, including the total plan metric in the floating strip.
Dependable reset alerts: Restrained strip animations and Windows notifications for meaningful scheduled or surprise resets, with startup replay, promotional pools, and alert bursts suppressed.
Tray-native behavior: Minimizing hides Ceiling to the system tray, and clicking the tray icon reliably restores the dashboard to the foreground.
Privacy and reliability
Ceiling is local-first. Credentials and usage data stay on your PC, and browser cookies, API keys, and local sign-in sources remain opt-in.
This release also hardens provider-window changes, stale history handling, notification throttling, dependency security, and the signed Windows release pipeline.
Downloads
Ceiling-0.43.2-Setup.exe is recommended for normal installation,